Full Report
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
Analysis Summary
# Threat Actor: WaterPlum
## Attribution & Identity
* **Identification:** North Korean state-sponsored cybercriminals.
* **Aliases:** WaterPlum (Collective tracking name used by international agencies).
* **Known Associations:** Attributed to the Democratic People's Republic of Korea (DPRK) regime; operates in coordination with the broader DPRK "IT Worker" fraudulent employment scheme.
## Activity Summary
WaterPlum is a sophisticated campaign involving fake recruiters who target jobseekers in the technology and decentralized finance (DeFi) sectors. The actors conduct fraudulent interview processes, tricking candidates into downloading malicious coding tests. As of late 2026, the campaign has successfully infected over 30,000 devices, compromised more than 7,000 cryptocurrency wallets, and exfiltrated approximately $10.71 million to support the North Korean regime.
## Tactics, Techniques & Procedures
* **Social Engineering:** Posing as recruiters on professional networking platforms to target high-value IT professionals.
* **Phishing/Malicious File Delivery:** Instructing victims to download and execute files disguised as "coding assignments" or "recruitment tests."
* **Remote Access:** Deployment of Remote Access Trojans (RATs) to maintain persistent access to victim environments.
* **Information Theft:**
* Exfiltration of browser credentials and sensitive data.
* Monitoring clipboard contents and logging keystrokes.
* Theft of identity documents (IDs) for future impersonation.
* **Post-Compromise Lateral Movement:** Leveraging jobseekers' infected machines to gain access to corporate systems once the victim secures legitimate employment ("Supply Chain" of human talent).
* **AI Manipulation:** Use of AI face-swapping software during video interviews to bypass identity verification.
## Targeting
* **Sectors:** Cryptocurrency, Web3, Software Engineering, and Web Design.
* **Geography:** Global, with specific focus on Western and allied nations including Australia, Germany, Japan, and the United States.
* **Victims:** Individual jobseekers (30,000+ devices) and potentially their future employers.
## Tools & Infrastructure
* **Malware Families:** Remote Access Trojans (RATs) and Information Stealers (unspecified variants).
* **Infrastructure:**
* **C2:** Command and Control servers used for data exfiltration and persistent access.
* **Laptop Farms:** Used by associated IT workers to mask their physical location.
* **Advisory Reference:** hxxps[://]www[.]ic3[.]gov/CSA/2026/260918[.]pdf
## Implications
This actor represents a dual threat: direct financial loss through cryptocurrency theft and long-term espionage/extortion risks. By compromising jobseekers *before* they are hired, WaterPlum creates a "trojan horse" effect where infected devices are brought into secure corporate environments. Furthermore, the theft of identity documents fuels the wider DPRK strategy of placing fraudulent IT workers in sanctioned countries to generate illicit revenue.
## Mitigations
* **For Jobseekers:**
* Exercise extreme caution when asked to download executable files or repositories for coding tests; use sandboxed environments (e.g., Virtual Machines) to run such tests.
* Verify the identity of recruiters through multiple official channels.
* **For Employers:**
* **Vetting:** Conduct rigorous background checks and verify educational/employment history.
* **Interview Integrity:** Watch for signs of AI face-swapping (visual artifacts), background noise, or refusal to turn on cameras.
* **Technical Onboarding:** Implement strict "Bring Your Own Device" (BYOD) policies and conduct forensic scans of personal hardware if it is to be used for work.
* **Zero Trust:** Assume credentials may be compromised and enforce Multi-Factor Authentication (MFA).